Fumiko Satoh

dblp:65/6764 · DBLP profile ↗
← Back
13ranked-venue papers
5as first author
1since 2021 · last 2024
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 8 · 4 first-author · 1 since 2021Artificial intelligence and machine learning · 3Databases, data management, data science and information retrieval · 3 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 1Applied, interdisciplinary, general and emerging computing · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Software engineering, system software, and programming languages
2 papers
Program verification · 51% Program synthesis and code generation · 25% Services computing and microservices · 8%
Network and information security
1 paper
Authentication and access control · 100%

Topics — the 8 heaviest of 8, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Program synthesis and code generation
code translation
0.812024
Automated Validation of COBOL to Java Transformation · ASE 2024
Program verification
equivalence checking
0.812024
Automated Validation of COBOL to Java Transformation · ASE 2024
Program verification
semantic equivalence
0.812024
Automated Validation of COBOL to Java Transformation · ASE 2024
Program analysis
symbolic execution
0.212024
Automated Validation of COBOL to Java Transformation · ASE 2024
Software testing
test generation
0.212024
Automated Validation of COBOL to Java Transformation · ASE 2024
Services computing and microservices › service composition
composite web services
0.112011
Security Policy Composition for Composite Web Services · IEEE Trans. Serv. Comput. 2011
Services computing and microservices › service composition
web service composition
0.112011
Security Policy Composition for Composite Web Services · IEEE Trans. Serv. Comput. 2011
Authentication and access control
security policy
0.012011
Security Policy Composition for Composite Web Services · IEEE Trans. Serv. Comput. 2011

Methods — techniques the papers use, named apart from their topics

test generation · 0.8symbolic execution · 0.8large language model · 0.8policy composition rules · 0.2
YearPublicationVenuePosition
2024 Automated Validation of COBOL to Java Transformation
abstract
Recent advances in Large Language Model (LLM) based Generative AI techniques have made it feasible to translate enterpriselevel code from legacy languages such as COBOL to modern languages such as Java or Python. While the results of LLM-based automatic transformation are encouraging, the resulting code cannot be trusted to correctly translate the original code. We propose a framework and a tool to help validate the equivalence of COBOL and translated Java. The results can also help repair the code if there are some issues and provide feedback to the AI model to improve. We have developed a symbolic-execution-based test generation to automatically generate unit tests for the source COBOL programs which also mocks the external resource calls. We generate equivalent JUnit test cases with equivalent mocking as COBOL and run them to check semantic equivalence between original and translated programs. Demo Video: https://youtu.be/aqF_agNP-lU
Atul Kumar 0002, Diptikalyan Saha, Toshiaki Yasue, Kohichi Ono, Saravanan Krishnan, Sandeep Hans, Fumiko Satoh, Gerald Mitchell, Sachin Kumar 0011
ASE7
2020 Automating Domain Squatting Detection Using Representation Learning
abstract
Registering altered domain names with the purpose of confusing users and conducting malicious activities is one of the most widespread types of attacks on the Web, conforming a family of techniques known as domain squatting. Detecting these domains is a difficult task, given the large a mount of combinations and the massive and heterogeneous nature of the Web. In this work, we propose a set of models to firstly learn the distributional regularities from detected squatted domains, and from that, automatically generate realistic modified domains. Our goal is to proactively guide the generation of squatted domains towards malicious domains that exists but have not been detected yet. We conducted an empirical study for both typo-squatting and combo-squatting generation approaches against strong baselines on real world data, showing their feasibility and providing insights to support for proactive defense in the context of cloud security.
Pablo Loyola, Kugamoorthy Gajananan, Hirokuni Kitahara, Yuji Watanabe, Fumiko Satoh
IEEE BigData5
2018 Bug Localization by Learning to Rank and Represent Bug Inducing Changes
abstract
In software development, bug localization is the process finding portions of source code associated to a submitted bug report. This task has been modeled as an information retrieval task at source code file, where the report is the query. In this work, we propose a model that, instead of working at file level, learns feature representations from source changes extracted from the project history at both syntactic and code change dependency perspectives to support bug localization.
Pablo Loyola, Kugamoorthy Gajananan, Fumiko Satoh
CIKM3
2018 Content Aware Source Code Change Description Generation
abstract
We propose to study the generation of descriptions from source code changes by integrating the messages included on code commits and the intra-code documentation inside the source in the form of docstrings.Our hypothesis is that although both types of descriptions are not directly aligned in semantic terms -one explaining a change and the other the actual functionality of the code being modified-there could be certain common ground that is useful for the generation.To this end, we propose an architecture that uses the source codedocstring relationship to guide the description generation.We discuss the results of the approach comparing against a baseline based on a sequence-to-sequence model, using standard automatic natural language generation metrics as well as with a human study, thus offering a comprehensive view of the feasibility of the approach.
Pablo Loyola, Edison Marrese-Taylor, Jorge A. Balazs, Yutaka Matsuo, Fumiko Satoh
INLG5
2013 Total Energy Management System for Cloud Computing
abstract
Reducing the energy used in Cloud Computing is an important issue a sustainable society. There are many existing approaches for reducing energy use in data centers, but new approaches are needed in case of energy management of Cloud Computing. Cloud Computing involves decentralized data centers, so new flexible way for collecting energy consumption data becomes quite important. Many current approaches focus on reducing energy consumption by air handling equipment, however energy from IT resources also need to be optimized for a total energy management of Cloud Computing. For advanced energy management for Cloud Computing, we developed a Cloud energy management system with sensor management functions, with an optimized VM allocation tool to minimize energy consumption at multiple data centers. Our evaluations showed more than a 30% energy savings for the servers in our experimental environment. Our system can be extended to optimize energy usage from various perspectives, such as for minimizing electricity bills or carbon emissions.
Fumiko Satoh, Hiroki Yanagisawa, Hitomi Takahashi, Takayuki Kushida
IC2E1
2011 Security Policy Composition for Composite Web Services
abstract
An application based on the Service-Oriented Architecture (SOA) consists of an assembly of services, which is referred to as a composite service. A composite service can be implemented from other composite services, and hence, the application could have a recursive structure. Securing an SOA application is an important nonfunctional requirement. However, specifying a security policy for a composite service is not easy because the policy should be consistent with the policies of the external services invoked in the composite process. Therefore, this paper proposes a security policy composition mechanism that uses the existing policies of the external services. Our contribution is defining the process-independent policy composition rules and providing a method for semiautomatically creating a security policy of the composite service. Our method supports two approaches of policy composition: top-down and bottom-up. Our study makes it possible to verify the consistency of the policies without increasing a developer's workload, even if the composite service has a recursive structure.
Fumiko Satoh, Takehiro Tokuda
IEEE Trans. Serv. Comput.1
2009 Static vs. Dynamic Validation of BSP Conformance
abstract
WS-I's basic security profile (BSP) defines best practice guidelines for secure Web services communications, enabling interoperability between vendors. However it is difficult for developers to know if their SOA solutions are in fact compliant to these guidelines. In this paper, we discuss methods to assess compliance against BSP. We have implemented runtime validation of SOAP messages to check for compliance against BSP, a method implied by the BSP definition itself. Additionally, we have implemented a novel approach to statically validate WS security policies against BSP using Schematron. From our experiments dynamic validation for BSP compliance offers greater coverage but results in a significant overhead, while static validation is limited in its scope but extremely valuable since under reasonable assumptions it provides assurances about compliance prior to deployment. We conclude with a summation of our results and lessons for SOA practitioners.
Stefan Prennschütz-Schützenau, Nirmal Mukhi, Satoshi Hada, Naoto Sato, Fumiko Satoh, Naohiko Uramoto
ICWS5
2008 Security Policy Composition for Composite Services
abstract
An application based Service-Oriented Architecture(SOA) consists of an assembly of external services and the application is called as a composite service. Acomposite service could be implemented by other composite services hence the application could have a recursive structure, which is one of the features of SOA application. Securing an SOA application is an important non-functional requirement. However, specifying a security policy of a composite service is not so easy because the policy should keep the consistency with other policies of external services which are invoked in the process. We need the way to assure the consistency of policies, but the concrete way is not developed yet to specify a consistent policy for a composite service. Therefore, this paper proposes a security policy composition mechanism from existing policies of external services. Our contribution is creating a security policy of a composite service automatically based on predicate logic, with support for two approaches of policy composition: bottom-up and top-down. Also, we focus on three kinds of security policies, such as a Data Protection Policy, an Access Control Policy, and a Composite Process Policy, and propose the policy composition rules for each policy. Our mechanism makes it possible to validate the consistency of policies by inference without increasing a developer's workload, even if a composite service has a recursive structure.
Fumiko Satoh, Takehiro Tokuda
ICWE1
2007 Syntactic Validation of Web Services Security Policies
Yuichi Nakamura 0003, Fumiko Satoh, Hyen-Vui Chung
ICSOC2
2007 Verifying the Consistency of Security Policies by Abstracting into Security Types
abstract
The service-oriented architecture (SOA) makes application development easier, because applications can be built from existing services with a bottom-up methodology. However, it is difficult to determine if a desired new service can be built from existing services. Not only the functional consistency of the existing services, but also the consistency of their non-functional (such as security) aspects must be verified. Message protection is an aspect of security. Every service needs an appropriate security policy defining the protection of messages exchanged between the parties to the service. Because of the intricacy of the Web services security policy language, it is difficult to verify the consistency of the security policies. We are developing a method to verify the consistency of security policies by abstracting them. Each security policy is abstracted, and then attached as a security type to the corresponding service in the application model. The security type denotes a security level for message protection. The security developer defines the possible abstraction methods. In this paper, we define the constraint of abstraction methods based on the semantics of the policy language. And also we state verifying the consistency of security types by using information flow analysis.
Kouichi Ono, Yuichi Nakamura 0003, Fumiko Satoh, Takaaki Tateishi
ICWS3
2007 Generic Security Policy Transformation Framework for WS-Security
abstract
Model-driven security is a framework to configure WS-security easily. It generates a security policy written in WS-security policy to be transformed into platform-specific configuration files. Since the WS-security policy specification is quite complicated, it is difficult to directly map between a security policy and a configuration. We propose a generic security policy transformation framework using an intermediate model. The intermediate model structure is designed based on the WS-security message structure, because both a security policy and the configuration files correspond to one WS-security message, even though the WS-security policy is flexible in specifying security requirements. Our contributions are simpler transformation rules compared to direct mapping, the support for various platforms, and more flexible updates if the WS-security policy specification changes. We demonstrate the transformation using the intermediate model for WebSphere application server 6.0.
Fumiko Satoh, Yumi Yamaguchi
ICWS1
2006 Adding Authentication to Model Driven Security
abstract
As service-oriented architecture has become popular, security has been a critical issue in multiple security domains using the WS-security framework. The authentication requirements depend on the application semantics, but configuring authentication is very difficult for someone who is not a security expert, such as an application developer, because it is necessary to understand platform-specific security features and authentication mechanisms. To resolve these difficulties, we propose a framework for platform-independent security configuration based on the model driven architecture. In this paper, we introduce a security qualifier, which is an abstract annotation for specifying authenticated identity on a platform-independent model, and a security infrastructure model which is a model including the platform information required for creating security policies. These ideas make authentication configuration possible without understanding the platform-specific information, such as the federation of the security domain and the relationships of trust between the servers. Our framework allows a non-security expert to configure security easily. We show how to configure the authentication for an ID propagation scenario and discuss advantages of our framework compared to existing tools
Fumiko Satoh, Yuichi Nakamura 0003, Koichi Ono
ICWS1
2002 Learning personalized video highlights from detailed MPEG-7 metadata
abstract
We present a new framework for generating personalized video digests from detailed event metadata. In the new approach high level semantic features (e.g., number of offensive events) are extracted from an existing metadata signal using time windows (e.g., features within 16 sec. intervals). Personalized video digests are generated using a supervised learning algorithm which takes as input examples of important/unimportant events. Window-based features are extracted from the metadata and used to train the system and build a classifier that, given metadata for a new video, classifies segments into important and unimportant, according to a specific user, to generate personalized video digests. Our experimental results using soccer video suggest that extracting high level semantic information from existing metadata can be used effectively (80% precision and 85% recall using cross validation) in generating personalized video digests.
Alejandro Jaimes, Tomio Echigo, Masayoshi Teraguchi, Fumiko Satoh
ICIP (1)4